Skip to content
Search

Latest Stories

Google researcher links ransomware attack to North Korea

An security researcher with Google has found evidence suggesting that North Korean hackers may have carried out the "unprecedented" ransomware cyberattack that hit over 150 countries, including India.

Neel Mehta has published a code which a Russian security firm has termed as the "most significant clue to date", the BBC reported today.


The code, published on Twitter, is exclusive to North Korean hackers, researchers said.

Researchers have said that some of the code used in Friday's ransomware, known as WannaCry software, was nearly identical to the code used by the Lazarus Group, a group of North Korean hackers who used a similar version for the devastating hack of Sony Pictures Entertainment in 2014 and the last years hack of Bangladesh Central Bank.

Security experts are now cautiously linking the Lazarus Group to this latest attack after the discovery by Mehta.

Mehta has found similarities between code found within WannaCry and other tools believed to have been created by the Lazarus Group in the past, BBC reported.

Security expert Prof Alan Woodward said that time stamps within the original WannaCry code are set to UTC +9 - China's time zone - and the text demanding the ransom uses what reads like machine-translated English, but a Chinese segment apparently written by a native speaker, the report said.

"As you can see it is pretty thin and all circumstantial. However, it is worth further investigation," Woodward said.

"Neel Mehta's discovery is the most significant clue to date regarding the origins of WannaCry," said Russian security firm Kaspersky, but noted a lot more information is needed about earlier versions of WannaCry before any firm conclusion can be reached, it reported.

"We believe it is important that other researchers around the world investigate these similarities and attempt to discover more facts about the origin of WannaCry," it said.

Attributing cyberattacks can be notoriously difficult - often relying on consensus rather than confirmation, the report said.

North Korea has never admitted any involvement in the Sony Pictures hack - and while security researchers, and the US government, have confidence in the theory, neither can rule out the possibility of a false flag, it said.

Skilled hackers may have simply made it look like it had origins in North Korea by using similar techniques.

In the case of WannaCry, it is possible that hackers simply copied code from earlier attacks by the Lazarus Group.

"There's a lot of ifs in there. It wouldn't stand up in court as it is. But its worth looking deeper, being conscious of confirmation bias now that North Korea has been identified as a possibility," Woodward said.

Its the strongest theory yet as to the origin of WannaCry, but there are also details that arguably point away from it being the work of North Korea.

First, China was among the countries worst hit, and not accidentally - the hackers made sure there was a version of the ransom note written in Chinese. It seems unlikely North Korea would want to antagonise its strongest ally. Russia too was badly affected, the report said.

Second, North Korean cyber-attacks have typically been far more targeted, often with a political goal in mind.

In the case of Sony Pictures, hackers sought to prevent the release of The Interview, a film that mocked North Korean leader Kim Jong-Un. WannaCry, in contrast, was wildly indiscriminate - it would infect anything and everything it could, the report said.

Finally, if the plan was simply to make money, its been pretty unsuccessful on that front too - only around $60,000 has been paid in ransoms, according to analysis of Bitcoin accounts being used by the criminals.

With more than 200,000 machines infected, its a terrible return, the report said.

On Friday, Europol Director Rob Wainwright said: "The global reach is unprecedented. The latest count is over 200,000 victims in at least 150 countries and those victims many of those will be businesses including large corporations".

The most disruptive attacks were reported in the UK, where hospitals and clinics were forced to turn away patients after losing access to computers.

More For You

UK Weather Alert: June Heatwave to Hit 34°C, Breaking Records

The UK is bracing for potentially one of the hottest June days on record

iStock

UK set for one of the hottest June days with highs of 34°C

Key points

  • Temperatures may hit 34°C in Greater London and Bedfordshire
  • Amber alert in place across five regions due to health risks
  • Wimbledon’s opening day to be hottest on record
  • Risk of wildfires in London labelled “severe”
  • Scotland and Northern Ireland remain cooler

Hottest June day in years expected as second UK heatwave peaks

The UK is bracing for potentially one of the hottest June days on record, with temperatures expected to reach 34°C on Monday (30 June). The ongoing heatwave, now in its fourth day, is most intense across the South and East of England, particularly in Greater London and Bedfordshire.

Although there is a small chance of temperatures hitting 35°C, they are unlikely to surpass the all-time June record of 35.6°C set in 1976.

Keep ReadingShow less
Air India flight crash
Air India's Boeing 787-8 aircraft, operating flight AI-171 to London Gatwick, crashed into a medical hostel complex shortly after take-off from Ahmedabad on June 12.
Getty Images

Probing all angles in Air India crash, including sabotage: Minister

INDIA’s junior civil aviation minister said on Sunday that all possible angles, including sabotage, were being looked into as part of the investigation into the Air India crash.

All but one of the 242 people on board the Boeing 787-8 Dreamliner were killed when it crashed in Ahmedabad on June 12. Authorities have identified 19 others who died on the ground. However, a police source told AFP after the crash that the death toll on the ground was 38.

Keep ReadingShow less
Police may probe anti-Israel comments at Glastonbury

Moglai Bap and Mo Chara of Kneecap perform at Glastonbury Festival at Worthy Farm in Pilton, Somerset, Britain, June 28, 2025. REUTERS/Jaimi Joy

Police may probe anti-Israel comments at Glastonbury

BRITISH police said they were considering whether to launch an investigation after performers at Glastonbury Festival made anti-Israel comments during their shows.

"We are aware of the comments made by acts on the West Holts Stage at Glastonbury Festival this afternoon," Avon and Somerset Police, in western England, said on X late on Saturday (28).

Keep ReadingShow less
Three killed, dozens injured in India temple stampede

Police officials visit the site after a stampede near Shree Gundicha Temple, in Puri, Odisha, Sunday, June 29, 2025. (PTI Photo)

Three killed, dozens injured in India temple stampede

AT LEAST three people, including two women, died and around 50 others were injured in a stampede near the Shree Gundicha Temple in Puri, Odisha, Indian, on Sunday (29) morning, according to local officials.

The incident occurred around 4am (local time) as hundreds of devotees gathered to witness the Rath Yatra (chariot festival), Puri district collector Siddharth S Swain confirmed.

Keep ReadingShow less
F-35B jet

The UK has agreed to move the aircraft to the Maintenance Repair and Overhaul (MRO) facility at the airport.

Indian Air Force

F-35B jet still stranded in Kerala, UK sends engineers for repair

UK AVIATION engineers are arriving in Thiruvananthapuram to carry out repairs on an F-35B Lightning jet belonging to the Royal Navy, which has remained grounded after an emergency landing 12 days ago.

The jet is part of the HMS Prince of Wales Carrier Strike Group of the UK's Royal Navy. It made the emergency landing at Thiruvananthapuram airport on June 14. The aircraft, valued at over USD 110 million, is among the most advanced fighter jets in the world.

Keep ReadingShow less